- EPSS 0.65%
- Veröffentlicht 15.04.2014 23:13:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter containing directory traversal sequences.
- EPSS 0.9%
- Veröffentlicht 15.04.2014 23:13:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname in a parameter.
CVE-2014-2862
- EPSS 0.28%
- Veröffentlicht 15.04.2014 23:13:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perform actions via unknown vectors.
CVE-2014-2861
- EPSS 0.35%
- Veröffentlicht 15.04.2014 23:13:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes ...
CVE-2014-2860
- EPSS 0.2%
- Veröffentlicht 15.04.2014 23:13:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inject arbitrary web script or HTML via a crafted HTTP request to a (1) ColdFusion or (2) JavaScript component.
CVE-2014-2859
- EPSS 0.35%
- Veröffentlicht 15.04.2014 23:13:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.
CVE-2010-0468
- EPSS 0.33%
- Veröffentlicht 02.02.2010 17:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CVE-2005-4574
- EPSS 4.38%
- Veröffentlicht 29.12.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.
- EPSS 0.4%
- Veröffentlicht 29.12.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting ...